EMC RSA Authentication Manager CVE-2017-15546 SQL Injection Vulnerability
BID:102838
CVE-2017-15546 |Info
EMC RSA Authentication Manager CVE-2017-15546 SQL Injection Vulnerability
| Bugtraq ID: | 102838 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-15546 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2018 12:00AM |
| Updated: | Jan 22 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
EMC RSA Authentication Manager 8.2 SP1 Patch 6 EMC RSA Authentication Manager 8.2 SP1 Patch 5 EMC RSA Authentication Manager 8.2 SP1 Patch 4 EMC RSA Authentication Manager 8.2 SP1 Patch 2 EMC RSA Authentication Manager 8.2 SP1 Patch 1 EMC RSA Authentication Manager 8.2 SP1 EMC RSA Authentication Manager 8.2 |
| Not Vulnerable: |
EMC RSA Authentication Manager 8.2 SP1 Patch 7 |
Discussion
EMC RSA Authentication Manager CVE-2017-15546 SQL Injection Vulnerability
EMC RSA Authentication Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
EMC RSA Authentication Manager 8.2 SP1 P6 and prior are vulnerable.
EMC RSA Authentication Manager is prone to an SQL-injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query.
Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
EMC RSA Authentication Manager 8.2 SP1 P6 and prior are vulnerable.
Exploit / POC
EMC RSA Authentication Manager CVE-2017-15546 SQL Injection Vulnerability
Attackers can exploit this issue using browser.
The following example URI is available:
https://www.example.com:4000/xDashboard/html/jobhistory/jobDocHistoryList.action?model.jobHistoryId=1736687378927012979202234841133and 1=1
Attackers can exploit this issue using browser.
The following example URI is available:
https://www.example.com:4000/xDashboard/html/jobhistory/jobDocHistoryList.action?model.jobHistoryId=1736687378927012979202234841133and 1=1
Solution / Fix
EMC RSA Authentication Manager CVE-2017-15546 SQL Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
EMC RSA Authentication Manager CVE-2017-15546 SQL Injection Vulnerability
References:
References:
- EMC Homepage (EMC)
- ESA-2018-002: RSA® Authentication Manager SQL Injection Vulnerability (Seclists.org)